Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.3%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-21724
  • Grafana » Grafana » Version: 11.6.10
    cpe:2.3:a:grafana:grafana:11.6.10
  • Grafana » Grafana » Version: 11.6.11
    cpe:2.3:a:grafana:grafana:11.6.11
  • Grafana » Grafana » Version: 11.6.9
    cpe:2.3:a:grafana:grafana:11.6.9
  • Grafana » Grafana » Version: 12.1.5
    cpe:2.3:a:grafana:grafana:12.1.5
  • Grafana » Grafana » Version: 12.1.6
    cpe:2.3:a:grafana:grafana:12.1.6
  • Grafana » Grafana » Version: 12.1.7
    cpe:2.3:a:grafana:grafana:12.1.7
  • Grafana » Grafana » Version: 12.2.2
    cpe:2.3:a:grafana:grafana:12.2.2
  • Grafana » Grafana » Version: 12.2.3
    cpe:2.3:a:grafana:grafana:12.2.3
  • Grafana » Grafana » Version: 12.2.4
    cpe:2.3:a:grafana:grafana:12.2.4
  • Grafana » Grafana » Version: 12.2.5
    cpe:2.3:a:grafana:grafana:12.2.5
  • Grafana » Grafana » Version: 12.3.1
    cpe:2.3:a:grafana:grafana:12.3.1
  • Grafana » Grafana » Version: 12.3.2
    cpe:2.3:a:grafana:grafana:12.3.2
  • Grafana » Grafana » Version: 12.3.3
    cpe:2.3:a:grafana:grafana:12.3.3


Contact Us

Shodan ® - All rights reserved